fusion-devtools

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill specifies installation of the 'fusion-devtools' (fdev) CLI tool from the vendor's official package repository at 'statoil-proview.pkgs.visualstudio.com'. This source is associated with the vendor infrastructure.
  • [COMMAND_EXECUTION]: The skill uses the 'fdev' CLI to perform platform operations, including service discovery and REST API interaction. The documentation includes best practices for command safety, such as quoting paths to prevent shell glob expansion.
  • [COMMAND_EXECUTION]: Provides functionality to activate Azure Privileged Identity Management (PIM) roles using 'fdev pim azure activate'. This high-privilege operation is mitigated by an explicit instruction to confirm with the user before execution.
  • [COMMAND_EXECUTION]: The skill handles Azure AD access tokens via the CLI tool. It includes safety guardrails requiring the agent to redact or truncate tokens when presenting output to the user to prevent credential exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 09:00 AM
Security Audit — agent-trust-hub — fusion-devtools